CVE-2025-11413

A vulnerability was found in GNU Binutils 2.45. Affected is the function elf_link_add_object_symbols of the file bfd/elflink.c of the component Linker. The manipulation results in out-of-bounds read. The attack needs to be approached locally. The exploit has been made public and could be used. Upgrading to version 2.46 is able to address this issue. The patch is identified as 72efdf166aa0ed72ecc69fc2349af6591a7a19c0. Upgrading the affected component is advised.
Configurations

Configuration 1 (hide)

cpe:2.3:a:gnu:binutils:2.45:*:*:*:*:*:*:*

History

14 Oct 2025, 15:24

Type Values Removed Values Added
CPE cpe:2.3:a:gnu:binutils:2.45:*:*:*:*:*:*:*
First Time Gnu binutils
Gnu
References () https://sourceware.org/bugzilla/attachment.cgi?id=16362 - () https://sourceware.org/bugzilla/attachment.cgi?id=16362 - Broken Link
References () https://sourceware.org/bugzilla/show_bug.cgi?id=33452 - () https://sourceware.org/bugzilla/show_bug.cgi?id=33452 - Exploit, Issue Tracking
References () https://sourceware.org/bugzilla/show_bug.cgi?id=33456#c10 - () https://sourceware.org/bugzilla/show_bug.cgi?id=33456#c10 - Exploit, Issue Tracking
References () https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=72efdf166aa0ed72ecc69fc2349af6591a7a19c0 - () https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=72efdf166aa0ed72ecc69fc2349af6591a7a19c0 - Patch
References () https://vuldb.com/?ctiid.327349 - () https://vuldb.com/?ctiid.327349 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.327349 - () https://vuldb.com/?id.327349 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.665587 - () https://vuldb.com/?submit.665587 - Third Party Advisory, VDB Entry
References () https://www.gnu.org/ - () https://www.gnu.org/ - Product

08 Oct 2025, 18:15

Type Values Removed Values Added
References () https://sourceware.org/bugzilla/show_bug.cgi?id=33452 - () https://sourceware.org/bugzilla/show_bug.cgi?id=33452 -

07 Oct 2025, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-07 22:15

Updated : 2025-10-14 15:24


NVD link : CVE-2025-11413

Mitre link : CVE-2025-11413

CVE.ORG link : CVE-2025-11413


JSON object : View

Products Affected

gnu

  • binutils
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer

CWE-125

Out-of-bounds Read